Newbee Mall Unrestricted File Upload Vulnerability in UploadController

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in Newbee Mall version 1.0. The issue arises in the Upload function of the UploadController.java file, where manipulation of the File argument enables remote exploitation.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could lead to further attacks such as remote code execution, depending on the uploaded file type and the application's file handling procedures.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.0
exploitability
6.8
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.